{ "@context": "https://schema.org", "@type": "WebPage", "@id": "https://www.planaxion.com/en-ca/articles/what-is-a-cyberattack#webpage", "name": "What is a cyberattack? The 5 most common types and how to recognize them", "url": "https://www.planaxion.com/en-ca/articles/what-is-a-cyberattack", "inLanguage": "en-CA", "publisher": { "@type": "Organization", "@id": "https://www.planaxion.com/#organization", "name": "PlanAxion", "url": "https://www.planaxion.com/" } }

What is a cyberattack? The 5 most common types and how to recognize them

A cyberattack is an action taken by hackers to damage a system, access confidential information, or obtain money, and it targets businesses for two reasons: their data and their bank accounts.
•
image of an innovation lab (for an AI developer tools business)
Key takeaways
  • According to the 2026 Verizon Data Breach Investigations Report, the human factor is involved in 62% of breaches, and ransomware accounts for 48% of them.
  • According to Statistics Canada, 16% of Canadian businesses were affected by a cybersecurity incident in 2023, and recovery costs doubled to $1.2 billion.
  • According to the Canadian Anti-Fraud Centre, reported losses exceeded $704 million in 2025, with $67.9 million attributed to spear phishing (targeted emails) alone.
  • A large transfer requested by email should always be confirmed verbally through another channel (PlanAxion, 2026).

On a Monday morning, the accounting technician at a Laval-based distributor receives an email from her president: "Urgent, I'm in a meeting, please wire $48,000 to the attached supplier before noon." The tone is spot on, as is the signature. The only detail: the president never wrote that email. It’s a cyberattack, and it looks nothing like a movie about hackers.

The figures cited are from public reports (Verizon, Statistics Canada, Canadian Anti-Fraud Centre) and describe trends, not your specific exposure.

According to the 2026 Verizon Data Breach Investigations Report, which analyzes over 22,000 confirmed breaches in 145 countries, the human factor is present in 62% of breaches, and ransomware is involved in 48% of them.

What is a cyberattack and why does it target your business?

A cyberattack is an action carried out by hackers to damage a system, access confidential information, or obtain money, and it targets businesses for two reasons: their data and their bank accounts. It takes various, often subtle forms, and the victim sometimes takes weeks to realize it.

Modern hacking rarely exploits a spectacular technical flaw. It exploits a person in a hurry, a reused password, or a payment procedure without double verification. This is why a secure work environment, including for cybersecurity for remote work, begins with employee habits.

Key figures to keep in mind:

  • According to Statistics Canada, 16% of Canadian businesses were affected by a cybersecurity incident in 2023, and 30% of large businesses.
  • Also according to Statistics Canada, post-incident recovery costs doubled, from $600 million in 2021 to $1.2 billion in 2023, and 13% of affected businesses suffered a ransomware attack.
  • According to Verizon (2026), the median ransom paid was $139,875 USD, and 69% of victims did not pay.
  • According to the Canadian Anti-Fraud Centre, more than 112,000 reports and $704 million in losses were recorded in 2025, including $67.9 million for spear phishing.

How can you recognize malware hidden in a document?

Macro-type malware is a micro-program inserted into a document, sent to the victim, which activates when they click a button to "enable content." The attack relies on curiosity or concern: an unpaid invoice, a delivery notice, or an "unreadable" document that needs to be unlocked.

Two simple rules. Don't know the sender? Don't open the document. Is the document unreadable and the only way to read it is to press a button? Don't press it. A legitimate supplier will find another way to reach you.

How can you spot email phishing and Business Email Compromise (BEC)?

Email phishing takes two forms: mass fraudulent emails (password resets, package tracking) and Business Email Compromise (BEC), a patient attack that targets people authorized to make payments. The first can be identified in seconds. The second can brew for months.

For mass emails, check the salutations: a company you have purchased from knows your name; a fraudster rarely does. Be wary of an unknown sender who seems to know you. Hover your mouse over the link to see the real destination, often hidden by a URL shortener. Spelling mistakes remain a clue, but Verizon notes that generative AI has made fraudulent emails much cleaner.

For BEC, the scenario is well-rehearsed. Hackers target accounting or finance, infiltrate software that observes exchanges for weeks (who talks to whom, with what words, who approves what), then wait for the right moment: the boss is traveling, in a meeting, or unreachable. The fake email then arrives, marked "Urgent," requesting a large wire transfer abroad.

The defense can be summed up in one sentence: any major wire transfer requires verbal confirmation, by phone, at a known number. Most of the time, your boss will have no idea what you are talking about. You will have thwarted the attack, and that is the time to review the company's internal controls and application risks.

What is the difference between smishing and vishing?

Smishing is phishing via text message and vishing is phishing via phone call; both aim to obtain your personal and banking data, one through a link to click, the other through the pressure of a human voice. They work because the phone is always in our pocket and its small screen invites us to click to "see more."

Smishing uses familiar names: iCloud, your bank, Canada Post, or a fake Interac transfer to "accept." The right response is to do nothing: don't click, don't reply, and don't engage. Block the number, but stay alert—scammers have plenty more.

Verizon (2026) also observes that click-through rates on mobile vectors (text, voice) are 40% higher than via email in phishing simulations.

Vishing includes fake fraud accusations from Revenu Québec or the Canada Revenue Agency, the cruise you supposedly won every month, or the fake Microsoft technician. Hang up. Then, call the organization at their official number to warn them: other, less savvy people will receive the same call.

An urgent transfer requested by email is not an emergency: it’s a red flag.

What is ransomware and how can you protect yourself from it?

Ransomware is malicious software that blocks access to a system and encrypts data, then demands a ransom, often in cryptocurrency, in exchange for the promise of unlocking everything. It arrives via a downloaded attachment or an infected site, and it plays on fear, sometimes by accusing the victim of illegal acts.

Paying guarantees nothing. The software often remains in place, signaling a future attack. Statistics Canada reports that 88% of Canadian businesses that were victims of ransomware did not pay in 2023. Verizon notes that while the median ransom is decreasing, the share of breaches involving ransomware has climbed to 48%.

Protection is unglamorous but highly effective: keep everything updated (operating system, software, antivirus, firewall) and perform periodic backups stored offline or in the cloud, tested at least once a year. A backup that has never been restored is just a theory. If personal information is affected, Law 25 imposes notification obligations that are best understood before an incident occurs.

How can you reduce the risk of cyberattacks in your daily life?

Reducing the risk of cyberattacks relies on three habits: never click on an unsolicited link or attachment, confirm any unusual payment through a second channel, and keep up with updates and backups. Technology protects the work environment; vigilance protects everything else. Learning to detect an attack remains the most cost-effective way to avoid one.

Frequently asked questions

What are the most common types of cyberattacks in business?

The five most common forms are malware hidden in a document, email phishing (including Business Email Compromise or BEC), text message phishing (smishing), phone phishing (vishing), and ransomware. According to Verizon (2026), the human factor is present in 62% of breaches, which explains why these attacks target employees first.

How can you tell if an email is fraudulent?

Check four things: generic greetings when the sender should know your name, an unknown sender who seems to know you, a link whose true destination (visible by hovering) does not match the text, and a sense of urgency. Spelling mistakes are becoming a less reliable indicator, as generative AI has made fraudulent emails more polished.

What is Business Email Compromise (BEC)?

Business Email Compromise is a patient attack: hackers observe the exchanges of someone authorized to make payments, then send a fake email from the boss—who is supposedly unreachable—demanding an urgent wire transfer abroad. In Canada, spear phishing caused $67.9 million in reported losses in 2025, according to the Canadian Anti-Fraud Centre. The solution: confirm verbally.

Should you pay the ransom during a ransomware attack?

No, in the vast majority of cases. Paying guarantees neither the recovery of data nor the removal of the malicious software, which often prepares for a subsequent attack. According to Statistics Canada, 88% of Canadian victimized businesses did not pay in 2023. The real defense is a recent, offline backup that has been tested for restoration.

What should you do immediately after a cyberattack?

Isolate affected devices from the network, change compromised passwords, and enable multi-factor authentication, then notify your IT team or service provider. Document what happened and report the incident to the police and the Canadian Anti-Fraud Centre. If personal information is involved, Law 25 requires you to notify the Commission d’accès à l’information.